Encryption key for management controller

By storing the encryption key of the management controller in a secure enclave and using memory alias and access control mechanisms, the problem of vulnerability of the management controller encryption key is solved, effectively protecting the encryption key is achieved, and the security risks of the computing environment are reduced.

CN120372634APending Publication Date: 2025-07-25HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410914291.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-25
Filing Date
2024-07-09
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The encryption keys of the management controller are vulnerable to attacks, resulting in a wider threat to the computing environment, and the prior art is difficult to effectively protect the encryption keys of the management controller from unauthorized access.

Method used

Store the encryption key of the management controller in a secure enclave and allow the encryption engine to access the key through a memory alias mechanism, which cannot be accessed directly by the management controller itself, combining the access control mechanism and the key enable indicator to ensure that the key is provided to the encryption engine only when a legitimate request is requested.

Benefits of technology

Effectively protect the encryption key of the management controller to prevent it from being exploited for unauthorized operations in damaged situations, reducing the risk of the computing environment being attacked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372634A_ABST
    Figure CN120372634A_ABST
Patent Text Reader

Abstract

The invention relates to an encryption key for a management controller. In some examples, a secure device includes a secure processor to control access to an encryption key in a storage area protected by the secure device. The secure device also includes a storage area controller that receives a request for an encryption key from a cryptographic engine associated with the management controller, the request based on a memory alias provided by the management controller to the cryptographic engine, where the management controller is to invoke the cryptographic engine to encrypt data using the encryption key. Based on the request, the storage area controller provides the encryption key to the encryption engine.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Data encryption involves converting data from plaintext (data in its unencrypted form) to ciphertext (data in its encrypted form). Data is encrypted by applying an encryption function to the data using an encryption key. The encrypted data can be accessed by an entity having the decryption key. Thus, the encrypted data can prevent unauthorized access by any entity that does not possess the decryption key. BRIEF DESCRIPTION OF THE DRAWINGS

[0002] Some embodiments of the present disclosure are described with reference to the following drawings.

[0003] Figure 1 is a block diagram of a host system according to some examples.

[0004] Figure 2A and Figure 2B is a block diagram of an arrangement for enabling and disabling access to a management controller encryption key in a secure enclave according to some examples.

[0005] Figure 3 is a block diagram of a security device according to some examples.

[0006] Figure 4 is a block diagram of an encryption device according to some examples.

[0007] Figure 5 is a flowchart of a process according to some examples.

[0008] In all the drawings, the same reference numerals represent similar, but not necessarily identical, elements. These drawings are not necessarily to scale, and the sizes of some parts may be enlarged to more clearly illustrate the examples shown. Additionally, the drawings provide examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments provided in the drawings. DETAILED DESCRIPTION

[0009] An attacker may attempt to gain access to encrypted data by determining the key that can be used to decrypt the encrypted data. The key used to decrypt the encrypted data may be the same as or different from the key used to encrypt the data. If symmetric data encryption is employed, the same encryption key is used to encrypt and decrypt the data. If asymmetric data encryption is employed, the encryption key used to encrypt the data is different from the decryption key used to decrypt the encrypted data. As used herein, an "encryption key" may refer to the key used to encrypt the data or the key used to decrypt the encrypted data.

[0010] An attacker (e.g., a person, program, or machine) can break into a system to gain access to an encryption key, such as by retrieving the encryption key from memory or by monitoring a communication link (hardware - or software - based) over which the encryption key can be transmitted. Once the encryption key is compromised, the security of the system that uses the compromised encryption key may be jeopardized.

[0011] In some systems, a management controller can be used to perform management tasks in the system. A system including a management controller can be referred to as a "host system" that has an operating system (OS) separate from the management controller (referred to as the "host OS") and a central processing unit (CPU) (referred to as the "host CPU"). The management controller can perform some management tasks including security tasks that employ encryption keys. If the encryption key used by the management controller is compromised, then the management controller itself is compromised, and an attacker can use the compromised management controller to gain access to the host system that includes the compromised management controller and any other systems coupled to that host system. Additionally, the management controller can operate independently of the host CPU and the host OS executing on the host CPU. Due to the independent operation of the management controller, if the management controller is compromised, it can allow an attacker to perform covert unauthorized operations in the host system that the host CPU or the host OS cannot detect. A compromised management controller can be used as a launchpad for a broader attack outside of the host system, such as an attack on a network to which the host system is connected. A compromised management controller may be able to bypass or even modify security measures implemented in the host system or in the network. Thus, the entire computing infrastructure (e.g., a data center, a cloud system, or any other computing environment) of an organization including a host system with a compromised management controller is threatened. An attacker may steal data stored in the computing infrastructure, perform unauthorized operations in the computing infrastructure, cause errors or other damage in the operation of the computing infrastructure, or perform other unauthorized operations.

[0012] According to some embodiments of the present disclosure, a security enclave (SE) in a host system is used to securely store encryption keys (or more generally, secrets) that will be used by a management controller (MC) in management tasks of the host system. The encryption keys to be used by the management controller are referred to as "MC encryption keys". The security enclave includes a storage area (referred to as the "SE storage area") for storing the MC encryption keys, where the SE storage area is not accessible by the management controller. The management controller uses an encryption engine to apply data encryption using the MC encryption keys. Although the management controller cannot access the MC encryption keys stored in the SE storage area of the security enclave, the encryption engine can access the SE storage area such that the encryption engine can obtain the MC encryption keys from the SE storage area for encrypting data on behalf of the management controller.

[0013] According to some embodiments of the present disclosure, the management controller provides a memory alias to the encryption engine, and the encryption engine uses the memory alias to access the SE storage area to retrieve the MC encryption keys from the SE storage area. A memory alias refers to information that provides a reference to the location of the MC encryption keys in the SE storage area. For example, if the SE storage area includes multiple memory locations storing respective different encryption keys (including the MC encryption key), the memory alias can be in the form of a location identifier (e.g., location 1 or slot 1, location 2 or slot 2, etc.) to identify one of the memory locations in the SE storage area that includes the MC encryption key to be used by the management controller. Location "x" (where x refers to any one of N memory locations, N≥1) can refer to the memory location in the SE storage area from which the encryption engine will retrieve the MC encryption key.

[0014] In other examples, the memory alias can be in the form of a key identifier. Different key identifiers can identify different encryption keys in the SE storage area. In these latter examples, the management controller and the security enclave can coordinate with each other to map the memory identifier to the respective different memory locations in the SE storage area. Mapping information that can map the encryption key identifier of the MC encryption key to the memory location in the SE storage area can be created, for example, by the security enclave. The security enclave provides the mapping information to the management controller, and the management controller stores the mapping information in the memory of the management controller. The management controller can provide the key identifier of the MC encryption key to the encryption engine, and the encryption engine accesses the mapping information in the memory of the management controller to obtain the memory location of the MC encryption key in the SE storage area.

[0015] Techniques or mechanisms according to some embodiments of the present disclosure protect management controller encryption keys from unauthorized access, even when a management controller such as a BMC is compromised. Protecting the management controller encryption keys reduces the likelihood that a compromised management controller can be used as a launching pad for a broader attack on the computing environment.

[0016] Figure 1 FIG. 4 is a block diagram of a host system 100 that includes a host CPU 102 and a management module 104. Examples of the host system 100 can include any or some combination of the following: a computer (e.g., a desktop computer, a laptop computer, a tablet computer, a server computer, or other types of computers), a communication node (e.g., a switch, a router, a gateway, or other types of communication-enabled devices), a storage system, a gaming device, an Internet of Things (IoT) device, a household appliance, a vehicle, or any other type of electronic device.

[0017] The host CPU 102 can include one or more processors that form the processing resources of the host system 100. The host CPU 102 executes host machine-readable instructions such as a host OS 152, an application 154, system firmware 156 (e.g., basic input / output system (BIOS) code or unified extensible firmware interface (UEFI) code), or other software or firmware. The processor can include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuits. The "host" machine-readable instructions are different (and separate) from the machine-readable instructions (such as firmware or software) executed by other electronic components (separate from the host CPU 102). The host machine-readable instructions can be stored in a storage medium (not shown in FIG. 4). Figure 1 in FIG. 4).

[0018] In a further example, the host system 100 may not execute a host OS or an application, in which case the host OS 152 and the application 154 are omitted.

[0019] The management module 104 includes a baseboard management controller (BMC) 106 and a secure enclave 108. The BMC 106 is an example of a management controller that performs various management tasks of the host system 100. Details of the BMC are further described below. The host CPU 102 can be coupled to the BMC 106, for example, via an input / output (I / O) bridge (not shown), which is a device that interconnects different components.

[0020] The management module 104 can be implemented by an integrated circuit chip, a circuit board, or an arrangement of discrete electronic components. The BMC 106 performs various management tasks, which will be discussed further below. Although the BMC is involved in some examples, other types of management controllers can also be used in other examples. As used herein, "controller" can refer to one or more hardware processing circuits, which can include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or any or some combination of other hardware processing circuits. Alternatively, "controller" can refer to a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.

[0021] The BMC 106 is coupled to the secure enclave 108 via the bus 130. The bus 130 can refer to any type of communication link through which electronic components can communicate, such as a memory bus, a storage device bus, a network, or any other type of link (whether wired or wireless).

[0022] The secure enclave 108 (also referred to as a secure boundary or a secure perimeter) includes a subsystem of the management module 104, and access to and from this subsystem is more strictly controlled compared to access to other subsystems of the management module 104. For example, the secure enclave 108 is completely set within an encryption boundary. An "encryption boundary" can refer to a continuous boundary or perimeter that contains the logical and physical components of an encryption subsystem, such as the components of the secure enclave 108. According to some examples, the secure enclave 108 is isolated from components outside the secure enclave 108. The encryption boundary is defined using secure access mechanisms, such as using encryption or other types of access control to protect the components in the secure enclave 108 from unauthorized access by components outside the secure enclave 108.

[0023] The secure enclave 108 includes a secure enclave (SE) processor 110, which can perform various security-related functions of the management module 104, including generating and / or maintaining keys related to encryption operations, such as encryption keys for encrypting information or private keys for signing information. The SE processor 110 can also maintain security certificates, which are used to authenticate the identity of entities, such as users, programs, websites, organizations, devices, programs, or any other type of entity. Further examples of security-related functions that can be performed by the SE processor 110 include root of trust operations (including measuring information such as machine-readable instructions or other information, performing signature verification, performing decryption, performing authentication, etc.), generation of random numbers and entropy, or other security-related functions.

[0024] The secure enclave 108 also includes an SE key storage area 112 for storing one or more encryption keys. The SE key storage area 112 can be implemented using any arrangement of storage elements, such as one or more registers or as part of the memory in the secure enclave 108. The "memory" can be implemented using one or more memory devices, such as dynamic random access memory (DRAM) devices, static random access memory (SRAM) devices, flash memory devices, or any other type of memory device. A "register" refers to a small storage device (e.g., smaller in size than the memory), which can be implemented using latches or other types of storage elements.

[0025] The SE key storage area 112 can be part of a designated memory space (e.g., the memory space of the management module 104 or the memory space of the host system 100). In an example where the SE key storage area 112 is implemented using one or more registers, the one or more registers can be one or more memory-mapped registers, which are part of a designated memory space.

[0026] In Figure 1 the example, the SE key storage area 112 stores multiple encryption keys, including the encryption key EK1, the management controller (MC) encryption key (MC EK), and the encryption key EKy. More generally, the SE key storage area 112 can store only one encryption key, such as the MC EK. Different encryption keys are used for various different purposes. The MC EK is used for management tasks performed by the BMC 106 (or more generally, by the management controller of the host system 100).

[0027] Access to the SE key storage area 112 is controlled by a storage area controller 124 in the secure enclave 108, such that other entities of the host system 100 (including the BMC 106) will not be able to access the SE key storage area 112 without the secure enclave 108 first enabling such access.

[0028] In an example where the SE key storage area 112 is part of the memory in the secure enclave 108, the storage area controller 124 includes a memory controller capable of issuing read and write access commands to the memory to access memory locations, including the memory locations of the SE key storage area 112. In other examples where the SE key storage area 112 is implemented using one or more registers, the storage area controller 124 can be implemented using hardware access logic associated with the one or more registers. In a further example, the storage area controller 124 is implemented using the SE processor 110.

[0029] The BMC 106 includes a BMC processor 114 that executes machine-readable instructions (firmware and / or software) of the BMC 106 to perform management tasks of the BMC 106. The BMC 106 also includes a BMC memory 116, which can be internal or external to the BMC 106.

[0030] The BMC 106 may also include an encryption engine 118 for performing data encryption. In other examples, an external encryption engine 118A located outside the BMC 106 may be used instead of the internal encryption engine 118 in the BMC 106. In the latter example, the external encryption engine 118A is connected to the BMC 106 such that the BMC 106 can invoke the encryption engine 118A to perform data encryption in management tasks performed by the BMC 106.

[0031] As used herein, "engine" may refer to one or more hardware processing circuits, which may include any or some combination of a microprocessor, cores of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuits. For example, the encryption engine 118 or 118A may be a hardware encryption engine that performs data encryption using the hardware processing circuit of the encryption engine 118 or 118A (without executing machine-readable instructions).

[0032] Alternatively, "engine" may refer to a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits. In these examples, the encryption engine 118 or 118A may execute machine-readable instructions (e.g., firmware or software) to perform data encryption.

[0033] In some examples, the encryption engine 118 or 118A may perform data encryption according to the Advanced Encryption Standard (AES) algorithm established by the National Institute of Standards and Technology (NIST) of the United States. In other examples, the encryption engine 118 or 118A may apply different types of data encryption, such as according to the Rivest-Shamir-Adleman (RSA) algorithm, or according to various encryption protocols, including any other encryption algorithms of standardized encryption protocols, open-source encryption protocols, or proprietary encryption protocols.

[0034] The BMC 106 also includes a network interface 120 to allow the BMC 106 to communicate with entities external to the BMC 106 (and which may be external to the host system 100) via a network (e.g., a management network). The network interface 120 may include a transceiver for sending and receiving signals, and any protocol layer for managing communication according to the corresponding communication protocol.

[0035] Note that "encrypting" data can refer to encrypting plaintext data into an encrypted form, or decrypting encrypted data to obtain plaintext data. In some examples, the network through which BMC 106 communicates can be a secure channel, where data communicated through the secure channel is encrypted. BMC 106 can invoke encryption engine 118 to encrypt data to be sent through the secure channel, or decrypt encrypted data received through the secure channel. Other examples of scenarios where BMC 106 can encrypt or decrypt data are also applicable.

[0036] In accordance with some embodiments of the present disclosure, encryption engine 118 is provided with the MC EK in the SE key storage area 112 controlled by secure enclave 108. Note that although the subsequent discussion refers to encryption engine 118, it should be noted that the techniques or mechanisms according to some examples can also be applied to external encryption engine 118A.

[0037] Encryption engine (EE) 118 includes an EE key storage area 140 for storing key data 142. EE key storage area 140 can be implemented as part of control register 128 or other registers of encryption engine 118. Alternatively, the memory in key engine 118 can be used to implement EE key storage area 140. The key data 142 written to EE key storage area 140 can include the MC EK from the SE key storage area 112 in secure enclave 108.

[0038] Once the MC EK is provided, encryption engine 118 is able to use the MC EK to perform data encryption. However, BMC 106 itself (or more specifically, components of BMC 106 other than encryption engine 118 in examples where encryption engine 118 is part of BMC) cannot access the MC EK in SE key storage area 112. For example, BMC processor 114 cannot access the MC EK. In examples employing external encryption engine 118A, the entire BMC 106 cannot access the MC EK in SE key storage area 112.

[0039] Components of BMC 106 (other than encryption engine 118) are disabled from accessing the MC EK in SE key storage area 112 based on any one of the following techniques: BMC components are hardware-isolated from being able to read SE key storage area 112, BMC 106 is configured to not issue reads to SE key storage area 112, or any other disabling technique.

[0040] Since the BMC components (except for the encryption engine 118) cannot access the MC EK, even if the BMC 106 is compromised, e.g., due to corruption of the machine-readable instructions executed by the BMC processor 114, an attacker will not be able to use the compromised BMC 106 to gain access to the MC EK.

[0041] The SE key storage area 112 in the secure enclave 108 may include different memory locations, including the memory location 122-1 for storing the encryption key EK1, the memory location 122-2 for storing the MC EK, and the memory location 122-y for storing the encryption key EKy.

[0042] In some examples, to allow the encryption engine 118 to access the MC EK in the SE key storage area 112 of the secure enclave 108, the encryption engine 118 is provided with the MC EK memory alias 126 stored in the control register 128 of the BMC 106. The control register 128 can be implemented using the hardware registers of the encryption engine 118. In some examples, the MC EK memory alias 126 can be written to the control register 128 by the BMC processor 114, e.g., during the startup process (e.g., initial boot) of the BMC 106.

[0043] In addition to the MC EK memory alias 126, the control register 128 may also include other information, such as the configuration related to the encryption algorithm (e.g., AES algorithm) to be implemented by the encryption engine 118 when encrypting data. The control register 128 may include other information, such as control information for controlling the encryption engine 118 and status information for indicating the status of the encryption engine 118.

[0044] Based on the MC EK memory alias 126, the encryption engine 118 is able to obtain the MC EK from the memory location 122-2 in the SE key storage area 112 of the secure enclave 108. For example, the encryption engine 118 can issue a fetch request to the secure enclave 108 via the bus 120. The fetch request may include one or more signals, one or more messages, or any other information element for indicating a read of the memory location 122-2 including the MC EK.

[0045] As described above, a memory alias may include a location identifier that identifies a specific memory location of the SE key storage area 112. For example, the MC EK memory alias 126 may include a location identifier that identifies the memory location 122-2 (e.g., "Location 2" or "Slot 2"). Alternatively, the MC EK memory alias 126 may be in the form of a key identifier that can be mapped to a memory location in the SE key storage area 112 using mapping information (such as the mapping information 132 stored in the control register 128). Alternatively, the mapping information may be stored in a different memory.

[0046] The fetch request issued by the encryption engine 118 to the secure enclave 108 includes a location identifier obtained by the encryption engine 118 based on the MC EK memory alias 126 in the control register 128 of the encryption engine 118. The location identifier in the fetch request may be included in the MC EK memory alias 126. Alternatively, the encryption engine 118 may obtain the location identifier in the fetch request by mapping the key identifier in the MC EK memory alias 126 to a location identifier (e.g., by accessing the mapping information 132).

[0047] In response to the fetch request, the storage area controller 124 may determine whether to authorize access to the memory location 122-2. For example, the storage area controller 124 may access the key access control area 134, which stores access enable indicators (AEIs) associated with the corresponding encryption keys in the SE key storage area 112. The key access control area 134 may be implemented using one or more hardware registers or in the memory of the secure enclave 108.

[0048] If the AEI is set to a disable value (e.g., "0"), it indicates that access to the corresponding encryption key will be disabled. On the other hand, if the AEI is set to an enable value (e.g., "1"), it indicates that access to the corresponding encryption key is enabled. In Figure 1 the example, the key access control area 134 stores AEI-1, AEI-MC, ……, AEI-y. AEI-1 controls (enables or disables) access to EK1, AEI-MC controls access to the MC EK, and AEI-y controls access to EKy.

[0049] In response to a fetch request for memory location 122-2 including the MC EK received from the encryption engine 118, the storage area controller 124 determines the value of AEI-MC. If AEI-MC is set to a disabled value (e.g., "0"), the storage area controller 124 rejects the fetch request. The storage area controller 124 may send an error indication to the encryption engine 118 indicating that the fetch request has been rejected, or alternatively, that the key data value provided from memory location 122-2 of the SE key storage area 112 is an invalid value (e.g., a null value such as all zeros, or other null value). On the other hand, if AEI-MC is set to an enabled value (e.g., "1"), the storage area controller 124 authorizes the fetch request and sends the MC EK to the encryption engine 118. At this time, the encryption engine 118 may use the MC EK in an encryption operation including encrypting data using the MC EK.

[0050] Figure 2A An example of the secure enclave 108 enabling the encryption engine 118 to access the MC EK is shown. In Figure 2A this case, the SE processor 110 issues an MC EK enable indication 202 that sets the value of AEI-MC in the key access control region 134 to an enabled value (e.g., "1"). If the SE processor 110 has not already done so, then the SE processor 110 may also (at 204) write the MC EK to memory location 122-2 in the SE key storage area 112. The MC EK in memory location 122-2 in the SE key storage area 112 may be provided to the encryption engine 118 and stored as the MC EK 206 in the EE key storage region 140 of the encryption engine 118. The MC EK 106 may be used by the encryption engine 118 to encrypt data when requested by the BMC 106.

[0051] After the SE processor 110 writes the MC EK to memory location 122-2, the SE processor 110 may lock memory location 122-2 to prevent any modification of the contents of memory location 122-2 until the SE processor 110 unlocks memory location 122-2. The SE processor 110 may lock memory location 122-2 by setting an indicator for the storage area controller 124 to prevent the storage area controller 124 from writing to memory location 122-2.

[0052] Figure 2B An example of the secure enclave 108 disabling the encryption engine 118 from accessing the MC EK is shown. In Figure 2BIn [the above], the SE processor 110 issues an MC EK disable indication 212, which resets the value of AEI-MC in the key access control region 134 to a disabled value (e.g., "0"). The SE processor 110 also (at 214) clears the memory locations 122-2 to null values (e.g., all 0s). If requested by the encryption engine 118, the null values in the memory locations 122-2 rather than the MC EK can be provided to the encryption engine 118 and stored as null values 216 in the EE key storage region 140 of the encryption engine 118. In this case, the encryption engine 118 does not have the MC EK and thus will not be able to encrypt data when requested by the BMC 106.

[0053] In some examples, the SE processor 110 in the secure enclave 108 is able to monitor the BMC 106 to determine whether the BMC 106 is compromised. For example, the SE processor 110 can monitor the BMC 106 by requesting the BMC 106 to send an encrypted hash value of the machine-readable instructions (e.g., firmware or software) executed by the BMC 106. The encrypted hash value is generated by applying an encryption hash function to the machine-readable instructions. The SE processor 110 can compare the encrypted hash value with a target value, and if the values do not match, the SE processor 110 determines that the BMC 106 is compromised.

[0054] In response to detecting that the BMC 106 has been compromised, the SE processor 110 issues an MC EK disable indication 212 to the key access control region 134 ( Figure 2B ), which resets the AEI-MC value in the key access control region 134 to a disabled value (e.g., "0"). The SE processor 110 also (at 214) clears the memory locations 122-2 to null values (e.g., all 0s). The SE processor 110 can also cause a restart of the encryption engine 118, such that the encryption engine 118 will have to re-acquire the key data for encryption operations. However, at this point, the memory locations 122-2 contain null values, such that the encryption engine 118 is provided with null values as key data. Any encryption operations performed by the encryption engine 118 will produce invalid encrypted data because the key data is set to null values. If the encryption engine 118 cannot encrypt data correctly, then the BMC 106 will lose its ability to perform secure tasks involving data encryption, such as communicating over a secure channel.

[0055] Figure 3 is a block diagram of a security device 300 according to some examples of the present disclosure. The security device 300 can be, for example, the secure enclave 108. The security device 300 includes a security processor 302, such as Figure 1the SE processor 110 therein. The security processor 302 controls access to encryption keys (e.g., Figure 1 the SE key storage area 112) in the storage area protected by the security device 300 (e.g., Figure 1 the MC EK). This storage area can be part of the security device 300.

[0056] The security device 300 includes a storage area controller 304 for managing access to this storage area. The storage area controller 304 can be, for example, Figure 1 the storage area controller 124. The storage area controller 304 can perform various tasks.

[0057] Tasks of the storage area controller 304 include an encryption key request receiving task 306 for receiving a request for an encryption key from an encryption engine (e.g., Figure 1 118 or 118A in Figure 1 associated with a management controller (e.g., Figure 1 BMC 106 in ). The request is based on a memory alias provided from the management controller to the encryption engine (e.g.,

[0058] 126 in ). The management controller will call the encryption engine to encrypt data using the encryption key.

[0059] Tasks of the storage area controller 304 include an encryption key distribution task 308 for providing an encryption key to the encryption engine based on the request. The encryption key provided to the encryption engine can be stored as key data in the storage area of the encryption engine.

[0060] In some examples, the security device 300 stores an access enable indicator associated with a memory location in the storage area, where the memory location is used to store the encryption key. The security processor 302 controls access to the encryption key in the storage area by setting the value of the access enable indicator.

[0061] In some examples, when set to a first value, the access enable indicator disables access to the memory location, while when set to a different second value, the access enable indicator enables access to the memory location.

[0062] In some examples, the storage area includes a plurality of memory locations to store respective encryption keys including an encryption key associated with the management controller. The security device 300 may store a plurality of access enable indicators associated with respective memory locations of the plurality of memory locations. The security processor 302 controls access to the plurality of storage areas by setting respective values of the plurality of access enable indicators.

[0063] In some examples, the security processor 302 writes an encryption key to a memory location in the storage area and, after writing the encryption key to the storage area, locks the memory location to prevent modification of the encryption key.

[0064] In some examples, the security processor 302 detects that the management controller is compromised and, based on detecting that the management controller is compromised, writes an invalid key value to the storage area to prevent use of the encryption key.

[0065] Figure 4 is a block diagram of an encryption device 400 according to some examples. The encryption device 400 may be, for example, Figure 1 the encryption engine 118 or 118A in

[0066] The encryption device 400 includes a memory 402, which may be implemented using any other arrangement of registers or storage elements. The encryption device 400 includes a controller 404 for performing various tasks. The tasks of the controller 404 may include a memory alias receiving task 406 for receiving a memory alias of an encryption key in a memory location in a secure enclave. The memory alias may be provided, for example, by the BMC processor 114, such as during the startup of the BMC 106.

[0067] The tasks of the controller 404 may include an encryption key receiving task 408 for receiving an encryption key from the secure enclave based on the memory alias. The controller 404 of the encryption device 400 may obtain the encryption key from the secure enclave by issuing a fetch request including a location identifier of the memory location including the encryption key.

[0068] The tasks of the controller 404 may include an encryption key storage task 410 for storing the encryption key (412) in the memory 402 of the encryption device 400. The tasks of the controller 404 may include a data encryption task 414 for encrypting data using the encryption key 412 (retrieved from the memory 402) as part of a security operation performed by the management controller, based on a call from the management controller to the encryption device.

[0069] In some examples, the processor of the management controller does not have access to the memory location in the secure enclave that includes the encryption key.

[0070] In some examples, the controller 404 determines a location identifier of a memory location based on a memory alias, and the controller 404 uses the location identifier to obtain an encryption key from the memory location in the secure enclave.

[0071] In some examples, the controller 404 determines the location identifier of the memory location by extracting the location identifier from the memory alias.

[0072] In some examples, the controller 404 determines the location identifier of the memory location by extracting a key identifier of the encryption key from the memory alias and accessing mapping information for mapping the key identifier to the location identifier.

[0073] Figure 5 is a flowchart of a process 500 according to some examples. The process 500 may be performed in a host system (such as Figure 1 the host system 100 in

[0074] The process 500 includes (at 502) executing machine-readable instructions on a processor of a management controller to perform management tasks of a host system including the management controller. The processor of the management controller may be, for example, Figure 1 the BMC processor 114 of

[0075] The process 500 includes (at 504) providing a memory alias of a memory location in a secure enclave to an encryption engine, where the memory location is for storing key data. In some examples, the memory alias may be provided by the management controller to the encryption engine.

[0076] The process 500 includes (at 506) receiving key data from the memory location at the encryption engine. The received key data may be an encryption key (if access to the encryption key is enabled in the secure enclave) or invalid null data (if access to the encryption key is disabled in the secure enclave).

[0077] The process 500 includes (at 508) using the key data for data encryption on behalf of the management controller by the encryption engine as part of the management tasks performed by the management controller. For example, the encryption engine performs data encryption on behalf of the management controller in response to being invoked by the management controller.

[0078] In some examples, the key data received from the memory location in the secure enclave at the encryption engine includes an encryption key that is accessible by the encryption engine but not by the processor of the management controller.

[0079] “BMC” (e.g., Figure 1The BMC (106) therein may refer to a dedicated service controller that uses sensors to monitor the physical state of an electronic device and communicates with a remote management system (i.e., away from the electronic device) via an independent "out-of-band" connection. The BMC can perform management tasks to manage the components of the electronic device. Examples of management tasks that the BMC can perform may include any or some combination of the following: power control for performing power management of the electronic device (such as transitioning the electronic device between different power consumption states in response to detected events), thermal monitoring and control of the electronic device (such as monitoring the temperature of the electronic device and controlling the thermal management state of the electronic device), fan control of the fans in the electronic device, system health monitoring based on monitoring measurement data from various sensors of the electronic device, remote access to the electronic device (e.g., accessing the electronic device via a network), remote restart of the electronic device (triggering a computer system restart using a remote command), system setup and deployment of the electronic device, system security for implementing security procedures in the electronic device, and so on.

[0080] In some examples, the BMC can provide a so-called "lights-out" function for the electronic device. The lights-out function can allow a user, such as a system administrator, to perform management operations on the electronic device even if the OS is not installed on the electronic device or is not functioning properly on the electronic device.

[0081] Furthermore, in some examples, the BMC can operate relying on auxiliary power (such as a battery) provided by an auxiliary power source; thus, the electronic device does not have to be powered on to allow the BMC to perform the operations of the BMC. The auxiliary power source is separate from the main power source that powers other components of the electronic device (e.g., the main processor, memory, input / output (I / O) devices, etc.).

[0082] According to some examples, the various tasks discussed herein can be implemented with machine-readable instructions that can be stored in a storage medium. The storage medium can include any or some combination of the following: semiconductor memory devices such as DRAM or SRAM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory; magnetic disks such as hard disks, floppy disks, and removable disks; other magnetic media including magnetic tape; optical media such as compact discs (CDs) or digital video discs (DVDs); or other types of storage devices. Note that the instructions discussed above can be provided on a single computer-readable or machine-readable storage medium, or alternatively, can be provided on multiple computer-readable or machine-readable storage media distributed in a large system that may have multiple nodes. Such a computer-readable or machine-readable storage medium or multiple storage media are considered to be part of an article (or article of manufacture). An article or article of manufacture can refer to any single manufactured component or multiple components. The storage medium or multiple storage media can be located in the machine that runs the machine-readable instructions, or can be located at a remote site where the machine-readable instructions can be downloaded over a network for execution.

[0083] In this disclosure, the use of the terms "a," "an," or "the" is intended to also include the plural forms unless the context clearly dictates otherwise. Additionally, when the terms "includes," "including," "comprises," "comprising," and "have," "having" are used in this disclosure, they specify the presence of the stated elements but do not preclude the presence or addition of other elements.

[0084] In the foregoing description, numerous details are set forth to provide an understanding of the subject matter disclosed herein. However, embodiments may be practiced without some of these details. Other embodiments may include modifications and variations of the details discussed above. The appended claims are intended to cover such modifications and variations.

Claims

1. A security device, comprising: A security processor for controlling access to an encryption key in a storage area protected by the security device; And A storage area controller for: Receiving a request for the encryption key from an encryption engine associated with a management controller, the request being based on a memory alias provided by the management controller to the encryption engine, wherein the management controller is used to call the encryption engine to encrypt data using the encryption key, and Providing the encryption key to the encryption engine based on the request.

2. The security device according to claim 1, wherein the storage area is inside the security device.

3. The security device according to claim 1, further comprising: An access enabling indicator associated with a memory location in the storage area for storing the encryption key, Wherein the security processor is used to control access to the encryption key in the storage area by setting the value of the access enabling indicator.

4. The security device according to claim 3, wherein the access enabling indicator disables access to the memory location when set to a first value, and enables access to the memory location when set to a different second value.

5. The security device according to claim 4, wherein the security processor is used to write an invalid key value to the memory location in the storage area while setting the access enabling indicator to the first value, and Among them, The security processor is used to write a valid key value to the memory location in the storage area while setting the access enabling indicator to the second value.

6. The security device according to claim 5, wherein when the access enabling indicator is set to the first value, the invalid key value is provided to the encryption engine in response to the request, and Among them, When the access enabling indicator is set to the second value, the valid key value is provided to the encryption engine in response to the request.

7. The security device according to claim 3, wherein the storage area includes a plurality of memory locations for storing respective encryption keys including the encryption key associated with the management controller.

8. The security device according to claim 7, comprising: A plurality of access enabling indicators associated with respective memory locations of the plurality of memory locations, Wherein the security processor is used to control access to the plurality of memory locations by setting respective values of the plurality of access enabling indicators.

9. The security device according to claim 1, wherein the security processor is used to: Write the encryption key to a memory location in the storage area, and After writing the encryption key to the storage area, lock the memory location to prevent modification of the encryption key.

10. The security device according to claim 1, wherein the security processor is used to: Detect that the management controller is compromised; and Based on detecting that the management controller is damaged, write an invalid key value to the storage area to prevent the use of the encryption key.

11. An encryption device, comprising: a memory; and a controller, the controller being configured to: receive a memory alias for an encryption key in a memory location in a secure enclave; receive the encryption key from the secure enclave based on the memory alias; store the encryption key in the memory of the encryption device; and as part of a security operation performed by the management controller, encrypt data using the encryption key based on a call to the encryption device by the management controller.

12. The encryption device according to claim 11, wherein, The memory location in the secure enclave containing the encryption key is inaccessible to the processor of the management controller.

13. The encryption device according to claim 11, wherein the controller is configured to: determine a location identifier of the memory location based on the memory alias; and obtain the encryption key from the memory location in the secure enclave using the location identifier.

14. The encryption device according to claim 13, wherein the controller is configured to: determine the location identifier of the memory location by extracting the location identifier from the memory alias.

15. The encryption device according to claim 13, wherein the controller is configured to: determine the location identifier of the memory location by: extracting a key identifier of the encryption key from the memory alias, and accessing mapping information that maps the key identifier to the location identifier.

16. A method, comprising: executing machine-readable instructions on a processor of a management controller to perform management tasks of a host system including the management controller; providing a memory alias for a memory location in a secure enclave to an encryption engine, the memory location for storing key data; at the encryption engine, receiving the key data from the memory location; and as part of the management tasks of the management controller, using the key data on behalf of the management controller by the encryption engine for data encryption.

17. The method according to claim 16, wherein the key data received at the encryption engine from the memory location in the secure enclave includes an encryption key that the encryption engine can access but the processor of the management controller cannot access.

18. The method according to claim 17, wherein the key data from the secure enclave includes the encryption key in response to the secure enclave enabling access to the memory location.

19. The method according to claim 18, wherein the key data received at the encryption engine from the memory location in the secure enclave includes an invalid value in response to disabling access to the memory location.

20. The method according to claim 16, wherein the encryption engine performs the data encryption on behalf of the management controller in response to being called by the management controller.